1 00:00:00,550 --> 00:00:03,700 Every site that you log into wants a capital letter, a 2 00:00:03,700 --> 00:00:05,590 number, and a special character. 3 00:00:06,090 --> 00:00:06,760 But guess what? 4 00:00:06,800 --> 00:00:10,620 None of that matters as much as how long your password is. 5 00:00:11,070 --> 00:00:14,240 Dr. Mike Saylor joins Prasanna and me to explain why. 6 00:00:14,690 --> 00:00:19,000 Mike is the co-author on Learning Ransomware Response and Recovery, 7 00:00:19,420 --> 00:00:24,210 and he's got receipts, including 20 terabytes of pre-computed password 8 00:00:24,210 --> 00:00:28,910 hashes that you can just go buy, uh, which is the reason that nobody even 9 00:00:28,910 --> 00:00:30,730 bothers cracking passwords anymore. 10 00:00:30,780 --> 00:00:31,720 They just look 'em up. 11 00:00:32,570 --> 00:00:36,210 There's a hard limit to how far these guys have gotten, and, uh, 12 00:00:36,230 --> 00:00:40,110 get past that limit and your risk goes way down, for now at least. 13 00:00:40,890 --> 00:00:45,420 We also get into why some LastPass customers lost everything and others 14 00:00:45,420 --> 00:00:51,130 didn't, whether passphrases actually work, and if forcing people to rotate their 15 00:00:51,130 --> 00:00:53,610 passwords does anything but annoy them. 16 00:00:54,520 --> 00:00:57,190 If this is your first time watching or listening to me, I'm 17 00:00:57,190 --> 00:00:59,720 W. Curtis Preston, AKA Mr. Backup. 18 00:01:00,150 --> 00:01:03,360 I've been obsessing about backup, recovery, and now cyber 19 00:01:03,360 --> 00:01:05,820 recovery for over 30 years. 20 00:01:06,190 --> 00:01:07,960 If that's your bag, I'm your guy. 21 00:01:08,540 --> 00:01:12,450 You're not gonna find anyone that cares about this topic more than me. 22 00:01:13,050 --> 00:01:17,460 Ever since 1993 when I had to tell my boss that there were no backups of 23 00:01:17,460 --> 00:01:19,100 the database that we had just lost. 24 00:01:19,860 --> 00:01:23,540 Now I've written five O'Reilly books, a blog, and this podcast. 25 00:01:23,950 --> 00:01:27,740 Here we turn unappreciated admins into cyber recovery heroes. 26 00:01:28,040 --> 00:01:29,910 This is the Backup Wrap-Up 27 00:01:43,376 --> 00:01:44,756 Welcome to the Backup Wrap Up. 28 00:01:44,786 --> 00:01:48,516 I'm your host, W. Curtis Preston, and I have with me once again the flowing 29 00:01:48,516 --> 00:01:51,666 mane of hair from Prasanna Malaiyandi. 30 00:01:51,736 --> 00:01:52,626 How's it going, Prasanna? 31 00:01:53,256 --> 00:01:54,316 I'm good, Curtis. 32 00:01:54,786 --> 00:01:56,056 I know. 33 00:01:56,326 --> 00:01:58,416 I was like, "Who is he talking about?" 34 00:01:58,630 --> 00:02:00,760 Yeah, I think we know who we're not talking about. 35 00:02:00,850 --> 00:02:01,540 Just saying. 36 00:02:02,370 --> 00:02:03,190 You doing all right over there? 37 00:02:03,320 --> 00:02:06,710 could also say his beard is, know 38 00:02:07,814 --> 00:02:11,234 Yeah, I'm just, I'm just, I'm trying to become Mike is what I'm doing 39 00:02:11,234 --> 00:02:14,714 here with the… It's just creeping further and further back on everything. 40 00:02:14,714 --> 00:02:17,694 But anyway, speaking of Mike, thanks for joining us again, Mike 41 00:02:17,999 --> 00:02:18,159 Sure. 42 00:02:18,159 --> 00:02:18,859 Thanks for having me. 43 00:02:19,377 --> 00:02:23,257 once again Dr. Mike Saylor, and he is my co-author on the book that 44 00:02:23,257 --> 00:02:26,077 is over my right sh- left shoulder. 45 00:02:26,267 --> 00:02:29,577 if you're watching us on YouTube, it is Learning Ransomware Response and 46 00:02:29,577 --> 00:02:32,137 Recovery, which, came out in, March. 47 00:02:32,387 --> 00:02:35,527 And, selling like hotcakes, at your local bookstore. 48 00:02:35,597 --> 00:02:38,687 I doubt it's at your local bookstore, but you can order it at your 49 00:02:38,687 --> 00:02:41,767 favorite internet-based bookstore, wherever that happens to be. 50 00:02:42,357 --> 00:02:45,557 and, I will say if you order it directly from O'Reilly, you and I 51 00:02:45,557 --> 00:02:48,817 make a little bit more money, but I don't know if anybody cares about that 52 00:02:49,633 --> 00:02:51,633 Is, is the audio version available? 53 00:02:52,147 --> 00:02:54,317 The audio version is available on, on Amazon. 54 00:02:54,737 --> 00:02:54,977 if 55 00:02:55,319 --> 00:02:56,889 ask me about that recently 56 00:02:56,983 --> 00:02:57,343 Yeah. 57 00:02:57,853 --> 00:02:58,203 Yeah. 58 00:02:58,813 --> 00:03:04,593 it is really weird to hear your book read to you by someone else. 59 00:03:05,173 --> 00:03:10,723 I just, I have actually listened to the audio version, and it was just odd, right? 60 00:03:10,833 --> 00:03:14,133 but yeah, it is available, and for those of you that like to listen 61 00:03:14,133 --> 00:03:17,543 to audiobooks, it's a page-turner. 62 00:03:17,593 --> 00:03:19,893 What do you call that with, in an audiobook version? 63 00:03:21,043 --> 00:03:23,463 Anyway, we're working through the book and going through a couple of 64 00:03:23,463 --> 00:03:26,103 different topics, and today we're talking about password managers. 65 00:03:26,643 --> 00:03:31,033 And we can talk about something that's come up a lot here, our least favorite 66 00:03:31,033 --> 00:03:34,703 password manager, that would be LastPass, and why is that, Prasanna? 67 00:03:34,713 --> 00:03:37,173 Why have they come up more than once on the pod? 68 00:03:38,287 --> 00:03:46,877 Boy, because they were and all of the password vaults that people were using 69 00:03:46,877 --> 00:03:52,037 were stolen, and then they sort of covered it up and said, "No, don't worry about 70 00:03:52,037 --> 00:03:55,427 it. It's okay. They didn't really get the password vault." And then it was found 71 00:03:55,427 --> 00:03:58,927 out they got the password vault, and then it was found out, yes, these password 72 00:03:58,937 --> 00:04:03,057 vaults could be cracked, and supposedly people with a bunch of cryptocurrency 73 00:04:03,067 --> 00:04:04,357 have had their wallets drained. 74 00:04:04,547 --> 00:04:09,037 Whether or not they're necessarily related, it's hard to say definitively, 75 00:04:09,037 --> 00:04:10,347 but it looks like there is a pattern 76 00:04:10,749 --> 00:04:13,829 I think at least one blogger says that he believes he has proof that 77 00:04:13,839 --> 00:04:18,369 the, the, that it, that what was happening is directly related to the, 78 00:04:18,369 --> 00:04:19,799 y- you know what I'm trying to say. 79 00:04:19,969 --> 00:04:20,299 Dang it. 80 00:04:20,883 --> 00:04:21,433 Oh, and, oh, one 81 00:04:21,479 --> 00:04:21,649 yeah 82 00:04:21,893 --> 00:04:26,913 add to that is, what ended up happening was LastPass was backing up the vaults, 83 00:04:27,293 --> 00:04:30,693 and they had a custom script in order to be able to do that, and they had 84 00:04:30,703 --> 00:04:35,373 hard-coded the password the script in order to be able to do the backups 85 00:04:36,783 --> 00:04:37,343 No bueno. 86 00:04:39,063 --> 00:04:42,913 The reason why that's relevant to the topic at hand is the people who had their 87 00:04:42,933 --> 00:04:48,433 passwords actually fully compromised were the ones that had passwords that 88 00:04:48,433 --> 00:04:51,083 were short enough to guess, right? 89 00:04:51,343 --> 00:04:56,603 and so because when you have a password manager that isn't a complete 90 00:04:56,603 --> 00:05:00,343 piece of crap, it's not storing the passwords in plain text, right? 91 00:05:00,343 --> 00:05:03,813 It's storing the passwords encrypted with some salt, right? 92 00:05:04,043 --> 00:05:09,233 So the only way to guess a password is to encrypt it similarly and then 93 00:05:09,283 --> 00:05:11,063 compare the encrypted result, right? 94 00:05:11,603 --> 00:05:16,633 And the people who had their passwords ultimately stolen via this hack is 95 00:05:16,633 --> 00:05:19,293 because their passwords were two things. 96 00:05:19,403 --> 00:05:23,053 They were short enough, and also they were encrypted with 97 00:05:23,063 --> 00:05:24,673 an older version of the product. 98 00:05:25,583 --> 00:05:29,803 And so it was, I think the salt was smaller or something like that, right? 99 00:05:30,403 --> 00:05:32,023 and so those two things together. 100 00:05:32,273 --> 00:05:38,863 So really when we put all that together, we have the phrase that comes up a lot, 101 00:05:38,903 --> 00:05:42,153 Mike, which is length over complexity. 102 00:05:42,623 --> 00:05:45,713 when we think about all of the things that we've done to make passwords more 103 00:05:45,713 --> 00:05:52,363 secure, one of the things anybody who's logged in any- anything in the last, 104 00:05:52,363 --> 00:05:58,073 I don't know, 20 years has been told, "Nope, that password's not secure enough. 105 00:05:58,073 --> 00:06:03,003 You need to add a, a capital letter." And then it's oh, you need to add a, a, 106 00:06:03,163 --> 00:06:06,293 you know a number. And then it's like, "Oh, you need to add a special character. 107 00:06:06,293 --> 00:06:10,103 No, not that special character." and, by the way, there's actually a comedian 108 00:06:10,523 --> 00:06:14,453 that I saw do this bit where he, Y- what, you know the one I'm talking 109 00:06:14,453 --> 00:06:19,073 about, right? Where he just one by one adds… Yeah, and so the people, they're 110 00:06:19,103 --> 00:06:23,013 like, hey, we're gonna change the S to a dollar sign. They'll never guess 111 00:06:23,013 --> 00:06:25,533 that." so that's complexity, right? 112 00:06:25,553 --> 00:06:27,613 The, making the password more and more complex. 113 00:06:27,613 --> 00:06:30,993 And I use a password manager, and one of the things that it 114 00:06:30,993 --> 00:06:34,313 does is it automatically creates a super complex password. 115 00:06:34,743 --> 00:06:39,453 But what do we mean when we say length over complexity? 116 00:06:41,823 --> 00:06:42,813 it's a math problem. 117 00:06:43,213 --> 00:06:46,603 so the longer your password is, the longer the math problem is. 118 00:06:47,693 --> 00:06:52,533 So if you've got a eight-character password, even with complexity, you're 119 00:06:52,533 --> 00:06:54,063 st- it's still eight characters. 120 00:06:54,773 --> 00:06:57,633 still the same eight-character math problem. 121 00:06:58,423 --> 00:07:04,103 that's a math problem if your is to do math, like I'm gonna 122 00:07:04,243 --> 00:07:05,653 try and crack this password. 123 00:07:05,673 --> 00:07:10,303 Nobody does that anymore, and they haven't for a long time. 124 00:07:10,343 --> 00:07:16,923 If you're a legit password-cracking bad person, you're gonna go buy tools, and 125 00:07:16,923 --> 00:07:20,653 you mentioned this already, if I've got an eight-character encrypted password, 126 00:07:20,683 --> 00:07:24,703 I just need to go encrypt stuff until the encryption, the, the encrypted 127 00:07:24,703 --> 00:07:27,033 password looks the same as this one. 128 00:07:27,503 --> 00:07:27,723 Right 129 00:07:27,783 --> 00:07:29,523 So that's a ha- they call that a hash. 130 00:07:29,753 --> 00:07:34,983 So the encrypted password results in a hash value, and that's 131 00:07:34,983 --> 00:07:37,133 the result of a math problem. 132 00:07:37,893 --> 00:07:42,643 I just need to go encrypt a bunch of stuff until I come up with the same math answer 133 00:07:43,763 --> 00:07:45,643 you went through to encrypt your password. 134 00:07:45,993 --> 00:07:52,003 there's a project, and it's been going on for years, called Rainbow Tables, 135 00:07:53,273 --> 00:07:58,773 and you can go to their website and buy six terabytes of math answers. 136 00:08:00,305 --> 00:08:02,875 Oh, where they've already encrypted, encrypted a bunch of passwords? 137 00:08:02,953 --> 00:08:03,783 still do this. 138 00:08:03,783 --> 00:08:06,963 they've done this 24 hours a day, seven days a week, across 139 00:08:06,993 --> 00:08:08,893 every platform that's out there. 140 00:08:09,353 --> 00:08:11,303 It's a nonprofit organization. 141 00:08:11,933 --> 00:08:12,913 that was my air quotes. 142 00:08:13,273 --> 00:08:19,253 and you can buy the entire database of encrypted hashes with the, 143 00:08:19,643 --> 00:08:22,383 respective clear text password. 144 00:08:22,873 --> 00:08:27,813 And so now you're not doing math, you're just comparing all the hashes 145 00:08:27,863 --> 00:08:31,533 that you wanna look up, and that's really what it is, and you're looking 146 00:08:31,533 --> 00:08:35,103 it up in this Rainbow Table database. 147 00:08:35,503 --> 00:08:40,213 I think the, the version we purchased, man, eight or years ago was, it was 148 00:08:40,213 --> 00:08:43,323 up to six terabytes of text files. 149 00:08:44,173 --> 00:08:44,283 A 150 00:08:45,189 --> 00:08:46,629 that's a lot of text files! 151 00:08:47,617 --> 00:08:50,267 And and just to give you an example of how much data that is, just 152 00:08:50,267 --> 00:08:52,357 doing the lookup took three days. 153 00:08:52,597 --> 00:08:54,057 That's how much data there was. 154 00:08:55,247 --> 00:08:59,357 But yeah, if I can get your encrypted eight-character password, your 155 00:08:59,367 --> 00:09:01,297 hash, I'm just gonna go look it up. 156 00:09:02,267 --> 00:09:05,767 That's why passwords are irrelevant today, and that's why it doesn't mean, 157 00:09:05,787 --> 00:09:11,567 it doesn't make sense to force users to change passwords every 30, 90, 100, and 158 00:09:11,567 --> 00:09:16,437 whatever days, unless you're a regulated industry that's a checkbox you gotta do. 159 00:09:16,867 --> 00:09:20,577 Because if a bad guy can get the hash, they can get the password 160 00:09:21,343 --> 00:09:25,213 Like, question for you on the hash, because I know sometimes when hashing 161 00:09:25,213 --> 00:09:27,003 you can pass in a salt, right? 162 00:09:27,023 --> 00:09:31,423 Or something, a variable, if you will, in order to ensure that what 163 00:09:31,423 --> 00:09:33,243 comes out isn't always the same. 164 00:09:33,733 --> 00:09:36,103 In the case of the passwords that are being generated and the 165 00:09:36,103 --> 00:09:39,023 hashes here, is that not the case? 166 00:09:39,827 --> 00:09:43,507 It is, and that's why I meant, so the, the rainbow tables, they're, 167 00:09:43,507 --> 00:09:47,717 creating these across all of the available systems in their project. 168 00:09:47,727 --> 00:09:51,147 So Linux, all the different flavors of Linux with Salt, Linux without 169 00:09:51,369 --> 00:09:51,379 Hmm. 170 00:09:51,657 --> 00:09:56,957 Windows, every version of Windows with LTM, LAN, hashing, on, with it 171 00:09:56,957 --> 00:10:00,407 turned off, Cisco VPN, Office 360. 172 00:10:00,417 --> 00:10:04,307 they're, everything that they can get their hands on to do these, math problems, 173 00:10:04,727 --> 00:10:07,927 they're doing it, and they're creating a catalog, and they're selling it 174 00:10:08,683 --> 00:10:12,983 Wonder, I wonder how many different types of systems they're doing that for 175 00:10:14,553 --> 00:10:16,633 I will ask while we are talking 176 00:10:18,533 --> 00:10:22,493 The, that, that's actually both fascinating and terrifying 177 00:10:22,863 --> 00:10:24,433 all, all at the same time. 178 00:10:24,873 --> 00:10:31,663 so i- if there's just a database then of all of the available passwords and hashes, 179 00:10:31,663 --> 00:10:36,873 z- from those passwords, why then do we care about, com- length of a password? 180 00:10:38,879 --> 00:10:40,079 'Cause it's still a math problem. 181 00:10:40,299 --> 00:10:44,169 so eight characters is obviously an easier math problem than 15 characters. 182 00:10:45,069 --> 00:10:48,579 but it also, lends itself to Difficulty. 183 00:10:49,289 --> 00:10:52,399 And so when someone sits down at your desk and tries to guess your 184 00:10:52,399 --> 00:10:55,329 password, they're gonna look around at all your notes and all that stuff, 185 00:10:55,339 --> 00:10:56,739 and they're gonna, my dog is hal. 186 00:10:58,329 --> 00:11:01,479 the longer that password is, the longer it's gonna take them to figure it out. 187 00:11:01,509 --> 00:11:04,099 And the more times they try to figure it out, hopefully you've got your 188 00:11:04,099 --> 00:11:09,329 system configured to that user account after so many failed login attempts 189 00:11:09,383 --> 00:11:14,693 Is it the case that given that this project has been running for 15 years, 190 00:11:14,933 --> 00:11:19,283 and given the fact that they have to, support, for lack of a better word, so 191 00:11:19,283 --> 00:11:23,333 many different systems, that they have to do this, this password, for every 192 00:11:23,333 --> 00:11:27,743 different system that they support, can we assume that they haven't gotten very 193 00:11:27,743 --> 00:11:30,223 far in terms of length of passwords? 194 00:11:31,375 --> 00:11:36,165 doing some research on the Rainbow Tables project, they, their hashing, 195 00:11:36,315 --> 00:11:43,655 activities include LM, NTLM, so LanMan, NT La- NT LanMan, MD5, SHA-1, 196 00:11:44,015 --> 00:11:48,375 and only-- they're currently only up to password length of 10 characters. 197 00:11:48,935 --> 00:11:53,765 And having done all of that, the database is currently at just over 20 198 00:11:53,765 --> 00:11:55,125 20 terabytes of text file 199 00:11:56,557 --> 00:12:02,117 they've yet to, to really expand, let's see, common hashes, MD5, 200 00:12:02,137 --> 00:12:05,287 SHA-1, SHA-256, and SHA-512 201 00:12:05,943 --> 00:12:06,323 Hey 202 00:12:08,027 --> 00:12:08,857 is where they're at. 203 00:12:09,605 --> 00:12:10,505 Like one of the things 204 00:12:10,647 --> 00:12:10,997 AES 205 00:12:11,055 --> 00:12:12,195 what does that mean, by the way? 206 00:12:12,205 --> 00:12:14,285 For the, for those that don't know what you're talking about, what, when 207 00:12:14,285 --> 00:12:18,285 we talk about SHA-1, SHA-256, SHA-5, what, what are you talking about there? 208 00:12:19,647 --> 00:12:24,717 So the MD5 is the fifth version of a, of an encryption or hashing algorithm. 209 00:12:26,067 --> 00:12:27,607 so fingerprinting a file. 210 00:12:28,457 --> 00:12:29,797 and the same thing with SHA. 211 00:12:29,847 --> 00:12:35,037 SHA-1 is the first version of SHA, and I can't remember what SHA stands for. 212 00:12:35,157 --> 00:12:40,357 but they're, they've been around forever, probably 40 years at 213 00:12:40,469 --> 00:12:40,969 Ever. 214 00:12:41,039 --> 00:12:41,349 Yeah. 215 00:12:42,557 --> 00:12:50,347 and then SHA-256 and SHA-512 are the size, so 256-bit, 5- 512-bit, the size of 216 00:12:50,347 --> 00:12:52,247 that encryption value or that hash value 217 00:12:53,471 --> 00:12:58,091 And so that, that, that's gonna… The, so when we say SHA-512, 218 00:12:58,121 --> 00:13:03,221 doesn't it mean that it's a f- is the, the hash is 512 bytes long? 219 00:13:03,241 --> 00:13:04,081 Is that what that means? 220 00:13:05,115 --> 00:13:05,715 That's correct. 221 00:13:05,851 --> 00:13:06,141 Yeah. 222 00:13:06,195 --> 00:13:12,635 similar like AES 256, AES 512, it's the, the, the bits in the encryption value. 223 00:13:13,505 --> 00:13:13,685 And 224 00:13:13,699 --> 00:13:14,029 But I'm 225 00:13:14,085 --> 00:13:19,565 when you, look at how long do I need… How long would it 226 00:13:19,565 --> 00:13:21,945 take to, to crack a SHA-512? 227 00:13:21,965 --> 00:13:25,355 It's like 300 years if you do the math. 228 00:13:26,085 --> 00:13:27,525 don't have to do the math anymore. 229 00:13:27,525 --> 00:13:31,635 You just have to compare… You just have to capture the hash then go compare it 230 00:13:31,645 --> 00:13:36,949 to somebody else that's already done the math or done the exercise the same hash. 231 00:13:37,609 --> 00:13:41,649 One, and by the way, those are all just current day problems. 232 00:13:42,519 --> 00:13:48,969 the quick evolution of quantum computing, even more complicated 233 00:13:49,889 --> 00:13:54,509 encryption and hash values that I can capture today, I don't have to wait 234 00:13:54,529 --> 00:13:56,959 300 years to break that, that math. 235 00:13:56,979 --> 00:14:01,429 I just have to wait another five or 10 until quantum computing's available 236 00:14:01,429 --> 00:14:05,409 for me to throw that at it and have it you know, decrypt it in real time. 237 00:14:05,977 --> 00:14:07,707 This is why people don't like you, Mike 238 00:14:09,229 --> 00:14:12,689 there's a whole lot of bad guys that are just, capturing encryption 239 00:14:12,689 --> 00:14:15,669 now s- and knowing that they'll be able to decrypt it in the next 240 00:14:15,669 --> 00:14:17,879 couple years in a fairly near term 241 00:14:18,445 --> 00:14:18,875 Yeah. 242 00:14:19,035 --> 00:14:19,285 See 243 00:14:19,369 --> 00:14:22,139 quantum safe algorithms now, right? 244 00:14:22,139 --> 00:14:26,759 In order to be able to handle the upcoming that yes, everything 245 00:14:26,759 --> 00:14:27,999 you're doing now can be cracked 246 00:14:30,103 --> 00:14:30,463 Right. 247 00:14:30,623 --> 00:14:34,873 But having said that, at least the current technology that's available, right? 248 00:14:34,873 --> 00:14:41,333 There is a table that we used in the book that, basically gives a, a certain 249 00:14:41,333 --> 00:14:44,853 number of years that it would take to crack a password of a certain length. 250 00:14:45,363 --> 00:14:49,393 And so I believe the current recommended size is at least 16 characters. 251 00:14:49,403 --> 00:14:50,783 Does that sound about right, Mike? 252 00:14:52,323 --> 00:14:53,113 I would say so. 253 00:14:53,113 --> 00:14:56,223 and a- along those lines, the longer the password gets, the 254 00:14:56,223 --> 00:14:59,413 more ridiculous the word gets, like supercalifragilistic, right? 255 00:14:59,413 --> 00:15:05,273 That might be a word, one-word password, but y- really gotta evolve, migrate 256 00:15:05,273 --> 00:15:07,943 away from passwords into passphrases. 257 00:15:08,367 --> 00:15:14,667 passphrases starts touching on the next evolution of MFA, that's cognitive MFA. 258 00:15:14,687 --> 00:15:17,827 It's like only you would know that part. 259 00:15:18,117 --> 00:15:22,877 only you have experienced that thing, so only you would know, what the 260 00:15:22,877 --> 00:15:26,647 missing piece is or what the answer to this question is or… it's very 261 00:15:26,647 --> 00:15:31,237 similar to, I wanna do my credit report, and so my credit, the reporting 262 00:15:31,237 --> 00:15:32,757 agencies know everything about you. 263 00:15:33,187 --> 00:15:36,197 And so it's not just your name, Social Security number, your date of birth. 264 00:15:36,207 --> 00:15:37,807 They're like, how much is your car payment? 265 00:15:38,247 --> 00:15:41,687 How much, when, what's the address you lived at when you were 20 years old?" 266 00:15:42,063 --> 00:15:42,373 Right 267 00:15:42,457 --> 00:15:45,417 So those are cognitive things, or for the most part. 268 00:15:45,417 --> 00:15:48,357 if I did enough reconnaissance on you, I could probably figure those things out. 269 00:15:49,123 --> 00:15:51,103 It wasn't breached or leaked 270 00:15:51,997 --> 00:15:52,457 Yeah. 271 00:15:52,667 --> 00:15:57,445 it's more personal than just the data that might be part a profile or 272 00:15:57,853 --> 00:16:01,063 what I find super frustrating is when I get one of those cognitive 273 00:16:01,123 --> 00:16:03,113 tests and I don't pass it. 274 00:16:03,343 --> 00:16:05,213 For me, that's very frustrating. 275 00:16:05,833 --> 00:16:09,573 They're like, "Which of the following, which of the following addresses 276 00:16:09,763 --> 00:16:12,513 is associated with you at some point?" And I'm like, I don't know. 277 00:16:12,523 --> 00:16:14,743 I think… I don't think it's any of them, but…" 278 00:16:14,773 --> 00:16:17,103 And then they're like, "Sorry, we could not, authenticate you." 279 00:16:17,997 --> 00:16:19,297 And that is a sneaky question. 280 00:16:19,297 --> 00:16:22,537 Sometimes they give you a list and the right answer is none of these. 281 00:16:22,975 --> 00:16:23,365 yeah. 282 00:16:23,995 --> 00:16:28,755 so I, I, that, by the way, I… Go ahead 283 00:16:29,797 --> 00:16:33,037 So Mike, it's interesting you talked about sort of moving 284 00:16:33,037 --> 00:16:34,647 from passwords to passphrases. 285 00:16:35,847 --> 00:16:42,257 Do you know if there's been re- Because I know s- sometimes it's hard to remember 286 00:16:42,257 --> 00:16:46,137 passwords, Which is why people in the past tended to use the same password 287 00:16:46,137 --> 00:16:48,187 over and over and over everywhere, right? 288 00:16:48,187 --> 00:16:49,317 Or some variation. 289 00:16:50,357 --> 00:16:55,837 passphrases, do you know if been research done to figure out, like, 290 00:16:56,097 --> 00:17:03,297 are people able to remember these a lot easier than the passwords that 291 00:17:03,297 --> 00:17:05,737 you used to have for individual sites? 292 00:17:07,315 --> 00:17:08,185 Don't know that. 293 00:17:08,305 --> 00:17:10,395 But I think the approach would be similar. 294 00:17:11,105 --> 00:17:14,435 so with your passwords, you're not supposed to use the same 295 00:17:14,455 --> 00:17:16,335 password for different things. 296 00:17:16,685 --> 00:17:18,885 So you've gotta come up with a way of remembering what 297 00:17:18,895 --> 00:17:20,555 password goes with what thing. 298 00:17:20,865 --> 00:17:22,865 very similar with your passphrase. 299 00:17:23,725 --> 00:17:26,875 passphrase should help you relate the phrase to whatever 300 00:17:26,875 --> 00:17:28,065 it is you're logging into. 301 00:17:28,075 --> 00:17:31,015 if you're logging into work, your passphrase could be, "I really 302 00:17:31,015 --> 00:17:33,995 wish I didn't work here," or, "I'd rather be fishing," right? 303 00:17:35,715 --> 00:17:40,295 so y- 'cause that's something you feel or comes to mind when you go to log in. 304 00:17:40,945 --> 00:17:45,005 versus your bank, I love rolling in cash." something like that. my 305 00:17:45,005 --> 00:17:48,865 account's not negative again." But, something that's related to what it is 306 00:17:48,865 --> 00:17:55,515 you're logging into is very helpful, and that's the, it's individualized. 307 00:17:55,525 --> 00:17:59,365 So whatever it is that you've had to do to remember the password for this 308 00:17:59,365 --> 00:18:03,975 thing, yeah, I think you would carry that forward to developing a passphrase 309 00:18:03,995 --> 00:18:05,625 for that, along those same lines 310 00:18:06,241 --> 00:18:11,791 The, I, I guess may- maybe because it was a pretty long time ago that I migrated 311 00:18:11,791 --> 00:18:15,741 to everything being in a password manager, and so I don't even, I don't 312 00:18:15,741 --> 00:18:20,181 even go down that… I never went down that path of thinking about passphrases. 313 00:18:20,521 --> 00:18:23,361 But I think if I would, if I did that, I would use it for 314 00:18:23,361 --> 00:18:25,571 a handful of accounts, right? 315 00:18:25,621 --> 00:18:30,231 Where, 'cause I, I can't… There's no way that my brain could remember the 316 00:18:30,231 --> 00:18:34,901 passphrases for as many as o- as many online accounts as I have, so that's 317 00:18:34,901 --> 00:18:36,571 why I've got to have a password manager. 318 00:18:36,571 --> 00:18:39,481 But I can see potentially using that, like you said, for logging 319 00:18:39,481 --> 00:18:46,151 into work, for logging into, a s- a smaller set of critical things. 320 00:18:46,391 --> 00:18:48,551 Is that, does that seem appropriate? 321 00:18:48,605 --> 00:18:52,345 and I'll add to that, we've talked about this Rainbow Tables project. 322 00:18:52,715 --> 00:18:56,075 When they're taking dictionary words and combinations of dictionary 323 00:18:56,075 --> 00:18:59,655 words, dirty cat, big dog, right? 324 00:18:59,665 --> 00:19:03,325 So they're doing that in an effort to create these encrypted 325 00:19:03,445 --> 00:19:05,075 hashes for your lookups. 326 00:19:05,815 --> 00:19:09,905 what becomes exponentially harder and will dura- you know, draw out 327 00:19:09,915 --> 00:19:14,455 the duration of their project so much longer are these passphrases. 328 00:19:15,115 --> 00:19:22,895 Curtis's password might be, "The big dog, eats steak." Prasanna's could 329 00:19:22,905 --> 00:19:26,275 be, "The big dog eats steaks," plural. 330 00:19:26,625 --> 00:19:32,605 those two passphrases are completely different and when you 331 00:19:32,935 --> 00:19:35,045 encrypt them and hash them, even though there was only one letter. 332 00:19:35,295 --> 00:19:41,705 then what if the big dog eats steaks, back to that, that comedian where, 333 00:19:41,715 --> 00:19:45,985 I'm gonna replace E's with threes, and I'm gonna capitalize the first 334 00:19:45,985 --> 00:19:48,155 letter of each word, things along… 335 00:19:48,165 --> 00:19:52,955 So that, that completely changes the hash value, and that, that is so much 336 00:19:52,965 --> 00:19:57,445 further down the line of the Rainbow Table project, math problems than 337 00:19:57,445 --> 00:19:59,355 just the simple word combinations. 338 00:19:59,755 --> 00:20:04,665 And many words there are in the American dictionary, guess, there, 339 00:20:04,665 --> 00:20:09,415 there's probably a math formula for figuring out how many passphrases 340 00:20:09,435 --> 00:20:12,405 that you can make in, 16 characters. 341 00:20:13,215 --> 00:20:17,405 Exponentially harder than the 10 character password combinations 342 00:20:17,937 --> 00:20:18,327 Yeah. 343 00:20:18,897 --> 00:20:26,717 So when we talk about work, is it, does it make sense to, for work 344 00:20:27,157 --> 00:20:32,097 passwords, where we're using passwords and not pass keys, does it make sense 345 00:20:32,097 --> 00:20:34,237 to mandate a password length then? 346 00:20:35,967 --> 00:20:36,407 Yes 347 00:20:37,809 --> 00:20:38,189 and, 348 00:20:38,307 --> 00:20:40,187 I think 16 characters is appropriate 349 00:20:40,585 --> 00:20:40,965 Yeah. 350 00:20:41,425 --> 00:20:44,085 By the way, speaking of things that annoy me, you know what annoys me? 351 00:20:44,345 --> 00:20:50,285 Is sites that go, "I'm sorry, your password is too long," or, "I'm sorry, 352 00:20:50,285 --> 00:20:54,685 but your password is, has a special character that we don't like." Those two 353 00:20:54,685 --> 00:20:59,445 things really annoy me, 'cause I've gone to 20 characters wherever I can, right? 354 00:20:59,755 --> 00:21:01,695 and and they're like, "I'm sorry, that's too big 355 00:21:03,003 --> 00:21:08,053 My favorite is thinking I'm using the right password, for it only to not 356 00:21:08,053 --> 00:21:10,093 work, and then I forgot my password. 357 00:21:10,173 --> 00:21:13,293 So you change your password to the one you thought you were using, and it says you 358 00:21:13,293 --> 00:21:15,063 can't change it to the current password. 359 00:21:16,553 --> 00:21:17,353 I just tried that 360 00:21:19,169 --> 00:21:20,199 Yeah, I've seen that. 361 00:21:20,299 --> 00:21:23,279 or the, the, "I'm sorry, you can't change it to that 'cause that was 362 00:21:23,279 --> 00:21:26,069 a previous password." some of them have they track the last three 363 00:21:26,069 --> 00:21:28,099 passwords and, and you can't change it 364 00:21:28,391 --> 00:21:28,691 too. 365 00:21:28,721 --> 00:21:33,101 I know it's frustrating to some people, important because that previous 366 00:21:33,121 --> 00:21:36,921 password may be the one that was compromised in some breach some time ago. 367 00:21:37,581 --> 00:21:41,131 So you're safe today because you're using a new password, but if 368 00:21:41,137 --> 00:21:41,327 Right 369 00:21:41,441 --> 00:21:43,911 to use an older password, it could have been one that was compromised. 370 00:21:44,581 --> 00:21:44,881 So 371 00:21:44,929 --> 00:21:45,809 And that's why they do it. 372 00:21:45,811 --> 00:21:46,401 good policy 373 00:21:46,929 --> 00:21:50,219 yeah, I, yeah, I'm not saying that was one ano- that annoys me, but 374 00:21:50,269 --> 00:21:55,019 it's annoying when it happens when you're trying to do something, right? 375 00:21:55,357 --> 00:21:56,497 And I'll add this too. 376 00:21:56,507 --> 00:22:00,627 I mentioned that 16 characters I think is appropriate, but it does depend on 377 00:22:00,637 --> 00:22:06,887 all the other stuff that you m- you're h- hopefully doing or could do mitigate 378 00:22:06,887 --> 00:22:11,537 the risk of an il- an illegitimate login or someone stealing your credentials. 379 00:22:11,537 --> 00:22:16,697 There are so many other settings and tools and layers that you could 380 00:22:17,167 --> 00:22:20,947 hopefully put in place or are in place that could mitigate the risk of a 381 00:22:20,997 --> 00:22:22,997 shorter password or even a compromised 382 00:22:25,643 --> 00:22:29,213 Prasanna, one of the things that we talk a lot about is password managers, 383 00:22:29,213 --> 00:22:34,063 and when we're talking about using this for work, there's thing we, 384 00:22:34,073 --> 00:22:38,153 there's a, there's enterprise-wide or commercial level password managers. 385 00:22:38,383 --> 00:22:39,823 y- you have any thoughts on that? 386 00:22:40,495 --> 00:22:45,895 yeah, no, I think enterprises should be using a password manager because 387 00:22:45,905 --> 00:22:51,385 otherwise people are gonna be y- storing passwords in their web browser or using 388 00:22:51,385 --> 00:22:55,405 the same passwords across multiple systems, all the rest of those things 389 00:22:55,405 --> 00:22:58,825 which you don't want as an enterprise, especially if you have, like, admin 390 00:22:58,835 --> 00:23:00,515 level accounts or things like that. 391 00:23:01,275 --> 00:23:05,935 And so I think going with an enterprise solution or a single sign-on solution, 392 00:23:05,935 --> 00:23:11,575 I know Microsoft has one with, I think it's now Entra, And, or you can look at 393 00:23:11,585 --> 00:23:15,625 Okta or any of these other companies in order to be able to provide this sort 394 00:23:15,625 --> 00:23:20,855 of mechanism so you don't necessarily need to remember all the passwords, 395 00:23:21,145 --> 00:23:25,715 which I know that SSO is slightly different than a password manager, but 396 00:23:25,715 --> 00:23:28,085 I think it sort of solves the same issue 397 00:23:29,377 --> 00:23:31,267 Yeah, SSO is very different, right? 398 00:23:31,277 --> 00:23:34,677 But you can connect a number of applications, especially SaaS 399 00:23:34,677 --> 00:23:41,327 applications, to your SSO and, it would, I would argue that a strong sing- s- 400 00:23:41,627 --> 00:23:47,767 a strong s- single sign-on system is probably, there's no probably, is more 401 00:23:47,767 --> 00:23:54,557 secure than 150 different passwords that I am forced to store in a password manager. 402 00:23:54,577 --> 00:24:00,867 If we can have a single, to go back to the previous episode, MFA protected, phishing 403 00:24:00,927 --> 00:24:06,997 resistant, MFA protected single password that I need to use for work, that is 404 00:24:06,997 --> 00:24:13,457 then going to have policies enforced on it, that to me is much more secure than 405 00:24:13,477 --> 00:24:18,157 any password manager, and that way you can say, "Just use this one password." 406 00:24:18,557 --> 00:24:22,337 Having said that, I'm still not a fan when we talk about like Entra 407 00:24:22,367 --> 00:24:26,407 ID, I'm still not a fan when we start talking about backup systems. 408 00:24:26,797 --> 00:24:31,357 I'm not a fan of having, them stored in the same whatever you have, 409 00:24:31,357 --> 00:24:36,207 either SSO or, password manager that you have for the company. 410 00:24:36,397 --> 00:24:39,057 I don't like that because if it's ultimately compromised, 411 00:24:39,087 --> 00:24:41,327 then, that's a, a problem. 412 00:24:41,837 --> 00:24:45,477 Mike, you talked a, a little bit about this and one, final thought about, 413 00:24:46,887 --> 00:24:53,657 passwords is that, this idea of forcing people to, automatically rotate. 414 00:24:53,687 --> 00:25:00,497 I know there's some situations where that might be a good idea, but in general, my, 415 00:25:00,517 --> 00:25:08,567 my opinion has been in general enforce a really long password and, a- and then not, 416 00:25:08,577 --> 00:25:10,907 and then don't force people to rotate it. 417 00:25:11,177 --> 00:25:12,287 Any, any thoughts on that? 418 00:25:14,459 --> 00:25:18,569 Yeah, this kind of goes back to my comment on, it depends. 419 00:25:18,979 --> 00:25:23,019 It depends on what else you're doing, and it depends on why you 420 00:25:23,029 --> 00:25:28,989 need to enforce a, a password change, whatever the frequency is. 421 00:25:28,989 --> 00:25:30,989 If it's six months or one year, why? 422 00:25:31,059 --> 00:25:32,139 Why are we doing that? 423 00:25:33,959 --> 00:25:36,059 regulatory compliance requires it. 424 00:25:36,719 --> 00:25:41,519 know, CMMC or the, cybersecurity maturity model for organizations 425 00:25:41,519 --> 00:25:45,659 that do business with the US government, have to have that setting. 426 00:25:45,689 --> 00:25:46,609 They have to do it. 427 00:25:47,059 --> 00:25:47,959 so why? 428 00:25:47,979 --> 00:25:48,909 Why do we have to do it? 429 00:25:49,059 --> 00:25:51,909 If you don't have to do it, why is it there? 430 00:25:52,699 --> 00:25:56,629 it there because we're lazy, and I need somebody to tell 431 00:25:56,629 --> 00:25:58,919 me when to change a password? 432 00:25:59,059 --> 00:26:04,029 Are we lazy on the IT side, where we're not reviewing system access enough, 433 00:26:04,229 --> 00:26:08,279 and I'm gonna rely on that password expiring to save my butt from having 434 00:26:08,549 --> 00:26:12,599 not disabled that user when they left two months ago, So there's that. 435 00:26:12,599 --> 00:26:13,219 it's why. 436 00:26:14,089 --> 00:26:19,499 if you can, absolutely enforce longer passwords, and if you've got other 437 00:26:19,499 --> 00:26:24,259 good controls in place like MFA, login and session restrictions, session 438 00:26:24,259 --> 00:26:30,249 timeouts, all these other good things, risky sign-ins, geographic limitations, 439 00:26:30,969 --> 00:26:35,469 concurrent logins, not being able to log in locally for, privileged accounts. 440 00:26:35,519 --> 00:26:39,069 there's so much you could do, and if you're doing good stuff, then absolutely 441 00:26:39,069 --> 00:26:41,019 you can rely on passwords a little longer 442 00:26:42,369 --> 00:26:48,279 The, the, the one thing I wanted to ask is, does your position 443 00:26:48,289 --> 00:26:52,089 change on password expiration if they're using a password manager? 444 00:26:54,019 --> 00:26:58,869 as a … Like, if for instance, the main password to access a password manager 445 00:26:59,819 --> 00:27:05,189 expired, but the individual passwords for the individual services rotated, as an end 446 00:27:05,189 --> 00:27:09,199 user, it's no different if I have to reset that password other than sort of having to 447 00:27:09,199 --> 00:27:11,599 go and go through the reset flow, right? 448 00:27:11,599 --> 00:27:15,689 But I don't need to remember anything other than my master password, right? 449 00:27:15,789 --> 00:27:18,289 So does it really make a difference? 450 00:27:19,855 --> 00:27:20,145 Depends. 451 00:27:20,595 --> 00:27:24,415 It's, I'm gonna get a shirt that just says, "It depends," or wear a hat. 452 00:27:24,465 --> 00:27:25,145 One of the two. 453 00:27:26,045 --> 00:27:26,755 it depends. 454 00:27:26,765 --> 00:27:30,175 So how religious are you at protecting your password 455 00:27:30,175 --> 00:27:31,785 manager and that one password? 456 00:27:32,245 --> 00:27:35,245 if, I'm able to get on your machine while you're doing your password 457 00:27:35,245 --> 00:27:38,415 manager, and I can see all that stuff, then it doesn't make any difference. 458 00:27:38,425 --> 00:27:43,125 If it's on a USB drive and you let your grandkids y- chew on that like a 459 00:27:43,125 --> 00:27:44,845 pacifier, it's probably not a good idea. 460 00:27:45,415 --> 00:27:49,955 j- it just, it truly depends, and it, and on a personal note, you've gotta, assess 461 00:27:49,955 --> 00:27:55,115 your own risk, and on, from a company perspective, it comes down to the weakest 462 00:27:55,115 --> 00:27:56,465 link, and the weakest link are people. 463 00:27:57,115 --> 00:27:59,545 And if you're relying on just that one pass- It's, and it's no 464 00:27:59,545 --> 00:28:00,755 different than single sign-on. 465 00:28:00,755 --> 00:28:05,295 Single sign-on is great from a usability and sometimes from a security perspective, 466 00:28:05,765 --> 00:28:12,025 but I've been on so many incident responses where the, the user credentials 467 00:28:12,025 --> 00:28:16,615 were compromised, legitimate-looking login to the environment that gave 468 00:28:16,625 --> 00:28:18,395 that bad guy access to everything. 469 00:28:19,505 --> 00:28:23,015 And so very similarly, it's just the one key that unlocks 470 00:28:23,085 --> 00:28:25,125 everything, and, I don't know. 471 00:28:25,345 --> 00:28:25,985 It depends 472 00:28:26,269 --> 00:28:29,199 That's sort of like the opposite of what you would want in cybersecurity 473 00:28:29,209 --> 00:28:32,739 with isolation and sort of fault domains and everything else. 474 00:28:33,467 --> 00:28:33,797 Yep. 475 00:28:34,257 --> 00:28:37,007 That's one of the reasons I'm glad the smart grid initiative fell 476 00:28:37,007 --> 00:28:41,017 apart, where all the people's, everybody's power meters and all that 477 00:28:41,065 --> 00:28:41,225 Mm-hmm. 478 00:28:41,347 --> 00:28:43,597 are all gonna be talking and all this, just 479 00:28:45,665 --> 00:28:48,105 Simplicity is the friend of the bad guys. 480 00:28:48,115 --> 00:28:49,505 You want complexity. 481 00:28:49,605 --> 00:28:53,795 The more complex something is, the less… more effort it's gonna take, 482 00:28:53,965 --> 00:28:56,315 and, bad guys are lazy for the most part. 483 00:28:56,619 --> 00:29:01,159 Yeah, it's that eternal war between complexity and usability, right? 484 00:29:01,199 --> 00:29:02,889 or security and usability, right? 485 00:29:02,889 --> 00:29:08,139 That you, again, my personal opinion for what it's worth is to simplify 486 00:29:08,139 --> 00:29:12,149 it as much as possible for the user, but add that security, right? 487 00:29:12,149 --> 00:29:15,459 If you make it too complex, if you make it too much of a pain in 488 00:29:15,459 --> 00:29:18,859 the butt, if they're able to go around it, they will go around it. 489 00:29:18,869 --> 00:29:21,709 and Mike, you talked about, in our pre-call, you talked about, 490 00:29:22,519 --> 00:29:25,139 an environment where you said that you would enforce something on 491 00:29:25,139 --> 00:29:26,449 laptops and then what happened? 492 00:29:28,327 --> 00:29:31,117 Yeah, I was hired by an organization to become their chief security 493 00:29:31,117 --> 00:29:33,177 officer because of a security event. 494 00:29:33,997 --> 00:29:39,317 event was, two field employees working out in the field, stopped at dinner somewhere. 495 00:29:39,377 --> 00:29:42,257 bad guys broke into their car, stole two laptops. 496 00:29:42,657 --> 00:29:47,797 The laptops had a combined three hundred years of client data on them. 497 00:29:49,067 --> 00:29:51,657 So they hired me to figure out what happened and how do we 498 00:29:51,817 --> 00:29:53,217 prevent this from happening again. 499 00:29:53,677 --> 00:29:58,267 One of the solutions was new laptops, 'cause the older ones couldn't… 500 00:29:59,497 --> 00:30:01,477 weren't capable of these new controls. 501 00:30:01,507 --> 00:30:08,047 New laptops, encrypt the hard drives, integrate the encryption password and 502 00:30:08,047 --> 00:30:14,747 the BIOS and the Windows into a So you, you log in with your credentials, you 503 00:30:14,747 --> 00:30:18,857 have to scan your fingerprint, and that's the multi-factor, something you know, 504 00:30:18,857 --> 00:30:21,427 something you have, or something you are. 505 00:30:21,767 --> 00:30:24,957 and then so we deployed that, fifty laptops out to the field. 506 00:30:25,497 --> 00:30:29,297 Forty-nine people complained and completely resisted, "We 507 00:30:29,297 --> 00:30:30,607 will not use this laptop." 508 00:30:30,847 --> 00:30:34,117 One other thing I do wanna add, as far as the description of the controls, 509 00:30:34,147 --> 00:30:39,747 the laptops had cameras, on the lid, and the camera would actively 510 00:30:39,747 --> 00:30:41,607 look for the presence of a person. 511 00:30:42,057 --> 00:30:44,127 So it's not, taking pictures of you. 512 00:30:44,127 --> 00:30:46,557 It just wants to know there's a person in front of the computer so 513 00:30:46,557 --> 00:30:49,707 that when I get up and move away, it automatically locks the screen. 514 00:30:50,267 --> 00:30:51,937 So just more security controls. 515 00:30:52,267 --> 00:30:56,337 But forty-nine of fifty people said, "It violates my privacy. I'm old, I don't 516 00:30:56,337 --> 00:31:02,817 have good fingerprints, so that's a, an accessibility violation." All this stuff. 517 00:31:02,867 --> 00:31:07,027 And so for all of the months of work we put into implementing security, 518 00:31:07,167 --> 00:31:09,797 politics defeated it all in a week. 519 00:31:10,107 --> 00:31:14,447 And we had to shut it off and let 'em do things the way they used to do it. 520 00:31:15,287 --> 00:31:16,387 But that was a business decision. 521 00:31:16,387 --> 00:31:17,402 It went Very well 522 00:31:18,364 --> 00:31:22,534 going back to something we talked about on the last episode, the idea being that 523 00:31:22,544 --> 00:31:26,464 perhaps this is something, these things like enforcing really long passwords, 524 00:31:26,774 --> 00:31:30,124 enforcing MFA, and other th- these things like you talked about with the 525 00:31:30,124 --> 00:31:35,834 laptops, that perhaps if you can start with the, the privileged accounts, right? 526 00:31:35,864 --> 00:31:40,644 It's a smaller number and it's, it's a group of people that theoretically 527 00:31:40,974 --> 00:31:42,284 would be, what do you call it? 528 00:31:42,624 --> 00:31:45,094 Would be more amenable to this type of control. 529 00:31:46,854 --> 00:31:47,284 All right. 530 00:31:47,484 --> 00:31:52,204 thanks again, Prasanna, for your, your wisdom as well 531 00:31:53,004 --> 00:31:56,134 I'm gonna figure out how long of a passphrase I can start creating. 532 00:31:56,134 --> 00:31:56,814 Thanks, Mike 533 00:31:58,796 --> 00:31:59,266 You're welcome. 534 00:31:59,276 --> 00:32:00,056 Mine's 24 535 00:32:02,342 --> 00:32:02,792 Nice. 536 00:32:03,232 --> 00:32:03,682 All right. 537 00:32:03,702 --> 00:32:05,912 And once again, thank you to the listeners. 538 00:32:05,932 --> 00:32:07,182 You're why we do this. 539 00:32:07,312 --> 00:32:08,462 And, buy my book. 540 00:32:08,792 --> 00:32:09,232 All right. 541 00:32:09,582 --> 00:32:10,152 Have a good day 542 00:32:13,130 --> 00:32:17,830 The Backup Wrap Up is written, recorded, and produced by me, W. Curtis Preston. 543 00:32:18,420 --> 00:32:23,180 If you need backup or DR consulting, content generation, or expert witness 544 00:32:23,180 --> 00:32:25,980 work, check out backupcentral.com. 545 00:32:26,490 --> 00:32:29,550 You can also find links for my O'Reilly books on the same website. 546 00:32:30,280 --> 00:32:34,250 Remember, this is an independent podcast, and any opinions that 547 00:32:34,250 --> 00:32:38,220 you hear are those of the speaker and not necessarily an employer. 548 00:32:39,090 --> 00:32:39,750 Thanks for listening